Description
WordPress Plugin BCS BatchLine Book Importer is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import/update arbitrary products. WordPress Plugin BCS BatchLine Book Importer version 1.5.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.8 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:23B76562-D2AF-4753-BCE4-002921F3378E
https://plugins.svn.wordpress.org/bcs-bertline-book-importer/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WP Print Friendly Cross-Site Scripting (0.6)
WordPress Plugin Limit Login Attempts Reloaded Cross-Site Scripting (2.15.2)
WordPress Plugin Backup Migration Cross-Site Scripting (1.1.5)
MySQL CVE-2013-5894 Vulnerability (CVE-2013-5894)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5491)